Moving Application logs deployed in OpenShift to Splunk

Viewed 54

We have a DotNet Core Application deployed in OpenShift. We have containerized it using Docker and deployed in OpenShift.

From the OpenShift Cluster level a Splunk Connector is setup. There will be specific indexes for object events and logs. The index is set on the connector config, and the Splunk information will be sent to Index specifically for OpenShift related logs.

We are planning to have Custom Index for our Container/Pod Question: Is there any best practice on how to configure the Log Stream from our application to a specific index that is different from the OpenShift Cluster itself ?

I am guessing there would be some SideCar kind of pattern that will help us, but unable to find a good resource on how to do it.

0 Answers
Related